Managed IT (MSP)
Running the estate day to day: identity and directory administration, endpoint management and patching, backup verification, monitoring, and the routine work that keeps things current. Scoped to an agreed service level rather than to a ticket count, because volume measures how much is going wrong rather than how well it is handled.
See also: IT Services
Managed security (MSSP)
Security monitoring and response: log collection, alert triage, investigation, and containment when something is real. The value is in triage rather than in the tooling. A service that forwards every alert has moved the problem to you rather than taken it on.
Managed detection and response
Endpoint and identity detection with the authority to act, agreed in advance: isolate a host, disable an account, kill a session. What we may do without calling you first is written into the agreement, because the middle of an incident is the wrong time to discover nobody has that authority.
Managed vulnerability management
The assessment cycle run as a service rather than as a series of engagements: recurring assessment, triage against your environment, and remediation tracked to closed. The same method as the standalone service, operated continuously.
See also: Vulnerability Assessment
Compliance evidence as a by-product
Both halves of a managed service generate exactly what an assessor asks for: patch records, access reviews, monitoring coverage, incident handling. Producing it continuously rather than reconstructing it under deadline is the single largest reason to buy IT and security management from a firm that also does your readiness work.
See also: Compliance Readiness
Escalation into the wider team
A managed service is the tier that handles the routine and knows when something is not routine. When it is not, the people who do the testing, the architecture, and the compliance work are in the same firm rather than at the other end of a referral.
See also: vCISO & Embedded Experts